Privacy Policy
Effective 28 September 2026
This policy explains what personal data ASGARD collects, why, and what you can do about it. It follows Qatar's Law No. 13 of 2016 on Protecting Personal Data Privacy (the "PDPPL") and, for people in the EU, EEA and UK, the GDPR (see section 12). Terms such as Client, Proposal, Project, Support & Growth Plan, Third-Party Platforms and Our Applications have the meaning given in our Terms and Conditions.
1. Who is responsible
ASGARD, a software development studio based in Doha, State of Qatar, is the controller of personal data processed through the website asgardhq.com (the "Website") and in our work with Clients and prospective Clients, except where we process personal data on a Client's behalf, as described in section 7. For anything about privacy, write to office@asgardhq.com.
2. What we collect
- When you visit the Website: the technical data needed to deliver and protect it: IP address, browser and device details, the page requested and the time; and anonymous usage statistics (see section 3). Cloudflare, which hosts the Website, processes this data.
- When you email us: your name, email address, the content of your message and attachments, and any details you choose to share about your business.
- When you work with us: contact details of your team, billing details, project materials and correspondence, and the accounts and data you give us access to for the Project.
We need contact and billing details to prepare a Proposal and to carry out a Project; without them we cannot work with you. Anything else you share is optional. If your employer or a colleague gives us your details for a Project, we receive them from them.
We do not ask for sensitive data (such as health, religion or criminal records), and we do not buy contact lists. We have no contact forms: you reach us by email.
3. No cookies, privacy-friendly statistics
The Website sets no cookies of its own and carries no advertising trackers or social-media pixels. Our fonts are served from our own site, so loading a page does not contact font providers.
To understand how the Website is used, we use Cloudflare Web Analytics. It does not use cookies or local storage, does not fingerprint your device, does not follow you across other websites and does not build a profile of you. When a page loads, a small script from Cloudflare records the page viewed, the referring page, the browser and device type, the country (derived from the IP address) and how fast the page loaded. We see only aggregated numbers, never individual visitors.
If bot protection is switched on, Cloudflare may set strictly necessary security cookies, such as __cf_bm (which expires after 30 minutes of inactivity) or cf_clearance (set after a visitor passes a check). They are used only to tell people from automated bots. Our Cloudflare account shows us aggregated traffic statistics and, for requests that trigger a security rule, individual log entries with the IP address, approximate location, browser details and page requested. We use them only to protect the Website, and they are kept only for the short periods described in section 8.
Because we do not track visitors over time or across other websites, and do not allow third parties to do so on the Website, the Website does not respond differently to browser "Do Not Track" signals.
4. Why we use your data
- to answer your messages and prepare Proposals;
- to deliver, support and invoice the Services;
- to keep the Website available and secure;
- to measure, in aggregate, how the Website is used and how fast it loads, so we can improve it;
- to keep the records the law requires, such as accounting records;
- to protect our legal rights.
We process personal data only with your consent or where it is necessary for a lawful purpose, as the PDPPL allows. We do not send you marketing emails without your prior consent, and we do not make decisions about you based solely on automated processing.
5. Who we share it with
We do not sell, rent or trade personal data. We share it with the following categories of recipients:
- Cloudflare: hosting, content delivery and security of the Website, and routing of emails sent to our addresses;
- Google: our email inbox (Gmail), where messages to office@asgardhq.com and support@asgardhq.com are delivered and stored;
- banks and payment providers that process your payments to us and our refunds;
- software providers we use to run projects and our business (for example code hosting, design, file-sharing and accounting tools), acting as our service providers;
- Third-Party Platforms and tools used in a Project, when needed to deliver it and as agreed with you;
- professional advisers, such as lawyers and accountants, who are bound by confidentiality;
- authorities, when the law requires it.
Cloudflare acts as our service provider (processor) under its data processing terms. Google provides our email inbox under Google's own terms and privacy policy (policies.google.com/privacy).
6. Transfers across borders
We are based in Qatar, and our service providers operate worldwide, so your data may be processed outside your country, including in the United States and the EU. We transfer data across borders only where this is consistent with the PDPPL and the data remains protected.
7. When we act for our Clients
In some Projects we process personal data of our Clients' own customers, for example conversations handled by an AI assistant or bot. For that data, the Client is the controller and ASGARD is a processor: we process it only on the Client's documented instructions, keep it confidential and secure, and use sub-processors (such as hosting, AI model and messaging providers) only as agreed with the Client. Where data protection law requires it, including the GDPR and UK GDPR, we sign a data processing agreement with the Client before we process that data; for Clients in the EU, EEA or UK it includes the EU Standard Contractual Clauses and the UK International Data Transfer Addendum. For other Clients it is available on request. If you are a customer of one of our Clients, please send requests about your data to that business; we will help it respond.
8. How long we keep it
- Website security data: for short periods, under Cloudflare's retention settings.
- Correspondence that does not lead to a Project: up to 24 months after our last exchange.
- Project materials and correspondence: for the Project and any Support & Growth Plan, then as agreed in the Proposal or data processing agreement.
- Contracts, invoices and accounting records: for as long as Qatari law requires.
- Portfolio materials: until you ask us to remove them.
After that, we delete or anonymise the data.
9. Security
We use encrypted connections, give access only to people who need it, and require our providers to protect data. No system is perfectly secure. If a breach is likely to harm you, we will notify you and the competent authority as the law requires.
10. Your rights
Under the PDPPL you may be told whether and why we process your data; access and review it and get a copy; ask us to correct it; object to processing that is not necessary for its purpose, or is excessive, discriminatory, unfair or unlawful; ask us to erase it in those cases or once the purpose has ended; be told if we have disclosed inaccurate data about you; and withdraw your consent at any time. Write to office@asgardhq.com. We may ask you to confirm your identity and will reply within 30 days. You can also complain to the National Cyber Security Agency (NCSA), the competent authority for personal data protection in Qatar.
11. Children
The Website and our Services are meant for businesses and adults. We do not knowingly collect personal data from anyone under 18. If you believe a child has sent us personal data, write to us and we will delete it.
12. If you are in the EU, EEA or UK
Where the EU General Data Protection Regulation (Regulation (EU) 2016/679), or the UK GDPR and the Data Protection Act 2018, apply to our processing:
- Legal bases. Answering enquiries and preparing Proposals: steps you ask for before a contract (Art. 6(1)(b)) or, if you write on behalf of a business, our legitimate interest in responding to business enquiries (Art. 6(1)(f)). Delivering, supporting and invoicing Services: performance of our contract with you (Art. 6(1)(b)) or, for people working for a Client, our legitimate interest in carrying out the Client's Project. Keeping the Website available and secure, including security logs: our legitimate interest in protecting the Website. Aggregated, cookie-free usage statistics: our legitimate interest in understanding and improving the Website. Keeping accounting and tax records: our legitimate interest in complying with the laws of Qatar that apply to us, and legal obligations under EU or UK law where they apply to us (Art. 6(1)(c)). Protecting our legal rights: our legitimate interest in establishing and defending legal claims. Marketing emails: your consent, which you can withdraw at any time.
- International transfers. Qatar does not have an adequacy decision from the European Commission or the UK. When you write to us, you send your data to us in Qatar. When we pass it on to service providers in other countries, including the United States, we rely on the standard contractual clauses (and the UK Addendum) in their data processing terms or, for certified US companies, the EU–US Data Privacy Framework and its UK Extension. You can ask us for a copy of these safeguards at office@asgardhq.com.
- Your right to object. You can object at any time to processing based on our legitimate interests, on grounds relating to your particular situation, by writing to office@asgardhq.com. We then stop, unless we have compelling legitimate grounds or need the data for legal claims.
- Your other rights. Access, rectification, erasure, restriction of processing, data portability, and withdrawal of consent.
- Complaints. You can complain to the data protection authority of the EU or EEA country where you live or work, or where you believe the infringement happened; in the UK, to the Information Commissioner's Office (ICO). You can also complain to us at office@asgardhq.com: we acknowledge your complaint within 30 days, look into it without undue delay and tell you the outcome.
13. Our Applications
Every application or platform that ASGARD itself releases and operates is governed by that application's own terms, privacy policy and refund rules, published inside or for it. For data processed in that application, its own privacy policy prevails over this one. This policy covers the Website and our bespoke client Services.
14. Changes
If this policy changes, the new version appears on the Website with a new effective date. If a change materially affects data you have already given us, we will tell you by email.
15. Contact
Privacy requests and questions: office@asgardhq.com